Nothing in Azure talks to anything else without a network underneath it, and that network is something you design, not something you get for free. This module covers how to build and secure that foundation: virtual networks and subnets, the rules that control what traffic is allowed in and out, and the services that connect networks together and spread traffic across them.
It starts with virtual networks and subnets — address spaces, IP addressing, and how to carve a VNet up into usable pieces. From there it covers network security groups, the inbound and outbound rules that filter traffic at the subnet or NIC level, and VNet peering and Azure DNS, for connecting networks to each other and resolving names within them. It closes with an Azure Load Balancer overview — distributing traffic across a pool of backend instances to keep an application available.
Work through the lessons in order, then continue on to Databases.
The networking chapter of John Savill's AZ-104 study cram: virtual networks, VNet peering, Azure Virtual Network Manager, network security groups, Azure Firewall, and both public and private Azure DNS.
John Savill's nearly 3-hour AZ-700 study cram, dedicated to Azure networking: virtual networks and subnets, peering, network security groups, DNS, load balancing, and hybrid connectivity — a deeper, networking-specific tour that ties this module's concepts together and doubles as certification prep.